Adobe Reader dc agm remote code execution vulnerability in CVE-2015-8458)
Adobe Reader dc agm remote code execution vulnerability in CVE-2015-8458)
Release date:
Updated on:
Affected Systems:
Adobe Reader DC
Description:
CVE (CAN) ID: CVE-2015-8458
Adobe Reader is a PDF document reading software. Acrobat is a PDF document editing software.
Acrobat Reader DC in AGM. dll implementation has a security vulnerability. a pdf with multiple layers may cause heap buffer overflow. Attackers can exploit this vulnerability to execute arbitrary code in the context of the current process.
<* Source: Fritz Sands-HPE Zero Day Initiative
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-637/
*>
Suggestion:
Vendor patch:
Adobe
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://helpx.adobe.com/security/products/acrobat/apsb15-24.html
This article permanently updates the link address: